Azure DevOps Server
by Microsoft
CVEs (20)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21564 | 0.01 | — | 0.06 | Feb 14, 2023 | Azure DevOps Server Cross-Site Scripting Vulnerability | |||
| CVE-2021-27067 | 0.01 | — | 0.12 | Apr 13, 2021 | Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability | |||
| CVE-2019-0996 | 0.01 | — | 0.08 | Jun 12, 2019 | A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, resulting in a cross-site request forgery. An attacker who successfully exploited this vulnerability could bypass OAuth protections and register an application… | |||
| CVE-2026-21512 | 0.00 | — | 0.00 | Feb 10, 2026 | Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network. | |||
| CVE-2024-35267 | 0.00 | — | 0.00 | Jul 9, 2024 | Azure DevOps Server Spoofing Vulnerability | |||
| CVE-2024-35266 | 0.00 | — | 0.00 | Jul 9, 2024 | Azure DevOps Server Spoofing Vulnerability | |||
| CVE-2024-20667 | 0.00 | — | 0.00 | Feb 13, 2024 | Azure DevOps Server Remote Code Execution Vulnerability | |||
| CVE-2023-21751 | 0.00 | — | 0.00 | Dec 13, 2023 | Azure DevOps Server Spoofing Vulnerability | |||
| CVE-2023-36437 | 0.00 | — | 0.01 | Nov 14, 2023 | Azure DevOps Server Remote Code Execution Vulnerability | |||
| CVE-2023-36561 | 0.00 | — | 0.00 | Oct 10, 2023 | Azure DevOps Server Elevation of Privilege Vulnerability | |||
| CVE-2023-38155 | 0.00 | — | 0.00 | Sep 12, 2023 | Azure DevOps Server Remote Code Execution Vulnerability | |||
| CVE-2023-33136 | 0.00 | — | 0.01 | Sep 12, 2023 | Azure DevOps Server Remote Code Execution Vulnerability | |||
| CVE-2023-36869 | 0.00 | — | 0.00 | Aug 8, 2023 | Azure DevOps Server Spoofing Vulnerability | |||
| CVE-2023-21569 | 0.00 | — | 0.00 | Jun 13, 2023 | Azure DevOps Server Spoofing Vulnerability | |||
| CVE-2023-21565 | 0.00 | — | 0.02 | Jun 13, 2023 | Azure DevOps Server Spoofing Vulnerability | |||
| CVE-2023-21553 | 0.00 | — | 0.01 | Feb 14, 2023 | Azure DevOps Server Remote Code Execution Vulnerability | |||
| CVE-2021-28459 | 0.00 | — | 0.01 | Apr 13, 2021 | Azure DevOps Server Spoofing Vulnerability | |||
| CVE-2020-17145 | 0.00 | — | 0.01 | Dec 9, 2020 | Azure DevOps Server and Team Foundation Services Spoofing Vulnerability | |||
| CVE-2020-17135 | 0.00 | — | 0.01 | Dec 9, 2020 | Azure DevOps Server Spoofing Vulnerability | |||
| CVE-2020-1325 | 0.00 | — | 0.02 | Nov 11, 2020 | Azure DevOps Server and Team Foundation Services Spoofing Vulnerability |
- CVE-2023-21564Feb 14, 2023risk 0.01cvss —epss 0.06
Azure DevOps Server Cross-Site Scripting Vulnerability
- CVE-2021-27067Apr 13, 2021risk 0.01cvss —epss 0.12
Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability
- CVE-2019-0996Jun 12, 2019risk 0.01cvss —epss 0.08
A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, resulting in a cross-site request forgery. An attacker who successfully exploited this vulnerability could bypass OAuth protections and register an application…
- CVE-2026-21512Feb 10, 2026risk 0.00cvss —epss 0.00
Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network.
- CVE-2024-35267Jul 9, 2024risk 0.00cvss —epss 0.00
Azure DevOps Server Spoofing Vulnerability
- CVE-2024-35266Jul 9, 2024risk 0.00cvss —epss 0.00
Azure DevOps Server Spoofing Vulnerability
- CVE-2024-20667Feb 13, 2024risk 0.00cvss —epss 0.00
Azure DevOps Server Remote Code Execution Vulnerability
- CVE-2023-21751Dec 13, 2023risk 0.00cvss —epss 0.00
Azure DevOps Server Spoofing Vulnerability
- CVE-2023-36437Nov 14, 2023risk 0.00cvss —epss 0.01
Azure DevOps Server Remote Code Execution Vulnerability
- CVE-2023-36561Oct 10, 2023risk 0.00cvss —epss 0.00
Azure DevOps Server Elevation of Privilege Vulnerability
- CVE-2023-38155Sep 12, 2023risk 0.00cvss —epss 0.00
Azure DevOps Server Remote Code Execution Vulnerability
- CVE-2023-33136Sep 12, 2023risk 0.00cvss —epss 0.01
Azure DevOps Server Remote Code Execution Vulnerability
- CVE-2023-36869Aug 8, 2023risk 0.00cvss —epss 0.00
Azure DevOps Server Spoofing Vulnerability
- CVE-2023-21569Jun 13, 2023risk 0.00cvss —epss 0.00
Azure DevOps Server Spoofing Vulnerability
- CVE-2023-21565Jun 13, 2023risk 0.00cvss —epss 0.02
Azure DevOps Server Spoofing Vulnerability
- CVE-2023-21553Feb 14, 2023risk 0.00cvss —epss 0.01
Azure DevOps Server Remote Code Execution Vulnerability
- CVE-2021-28459Apr 13, 2021risk 0.00cvss —epss 0.01
Azure DevOps Server Spoofing Vulnerability
- CVE-2020-17145Dec 9, 2020risk 0.00cvss —epss 0.01
Azure DevOps Server and Team Foundation Services Spoofing Vulnerability
- CVE-2020-17135Dec 9, 2020risk 0.00cvss —epss 0.01
Azure DevOps Server Spoofing Vulnerability
- CVE-2020-1325Nov 11, 2020risk 0.00cvss —epss 0.02
Azure DevOps Server and Team Foundation Services Spoofing Vulnerability